Policy Exception Requests

Policies API v1 endpoints for reading policy exception requests.

Read policy exception requests submitted for approval. The v1 API currently provides read access only. Create, approve, and reject exception requests from the Nirmata Control Hub console.

All paths are relative to /policies/api/v1. See Policies API v1 for authentication and conventions.

Endpoints

OperationMethodPath
List policy exception requestsGET/policy-exception-requests
Count policy exception requestsGET/policy-exception-requests/count
List pending exception requestsGET/policy-exception-requests/pending
Get a policy exception requestGET/policy-exception-requests/{id}
List exception requests for a clusterGET/policy-exception-requests/by-cluster/{clusterId}
List exception requests by requesterGET/policy-exception-requests/by-requester/{requestedBy}
List exception requests by stateGET/policy-exception-requests/by-status/{status}

Reference

List policy exception requests

GET /policies/api/v1/policy-exception-requests

Returns all policy exception requests in the tenant, paginated in memory with limit/offset.

Roles: admin

Query parameters

NameTypeRequiredDefaultDescription
limitintegerNo50Maximum items to return
offsetintegerNo0Number of items to skip

Response 200 (application/json)

Paginated: {items: PolicyExceptionRequest[], total, limit, offset}

FieldTypeDescription
idstringRequest ID
namestringRequest name
requestedBystringUser who submitted the request
requestedByEmailstringEmail of the requester
statusstringRequest state: pendingApproval | approved | rejected
requestTypestringType of exception request
justificationstringReason given by the requester

Errors

  • 500 — Failed to retrieve policy exception requests
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

Count policy exception requests

GET /policies/api/v1/policy-exception-requests/count

Returns the total number of policy exception requests in the tenant.

Roles: admin

Response 200 (application/json)

{count: integer}

FieldTypeDescription
countintegerNumber of requests

Errors

  • 500 — Failed to count requests
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List pending exception requests

GET /policies/api/v1/policy-exception-requests/pending

Returns all requests awaiting approval (state pendingApproval). Not paginated.

Roles: admin

Response 200 (application/json)

PolicyExceptionRequest[] (plain array)

FieldTypeDescription
idstringRequest ID
namestringRequest name
requestedBystringUser who submitted the request
requestedByEmailstringEmail of the requester
statusstringRequest state: pendingApproval | approved | rejected
requestTypestringType of exception request
justificationstringReason given by the requester

Errors

  • 500 — Failed to get pending requests
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

Get a policy exception request

GET /policies/api/v1/policy-exception-requests/{id}

Returns a single policy exception request by ID.

Roles: admin

Path parameters

NameTypeDescription
idstringPolicy exception request ID

Response 200 (application/json)

PolicyExceptionRequest

FieldTypeDescription
idstringRequest ID
namestringRequest name
requestedBystringUser who submitted the request
requestedByEmailstringEmail of the requester
statusstringRequest state: pendingApproval | approved | rejected
requestTypestringType of exception request
justificationstringReason given by the requester

Errors

  • 404 — Request not found
  • 500 — Failed to retrieve request
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List exception requests for a cluster

GET /policies/api/v1/policy-exception-requests/by-cluster/{clusterId}

Returns requests that target the given cluster. Not paginated.

Roles: admin

Path parameters

NameTypeDescription
clusterIdstringCluster ID

Response 200 (application/json)

PolicyExceptionRequest[] (plain array)

FieldTypeDescription
idstringRequest ID
namestringRequest name
requestedBystringUser who submitted the request
requestedByEmailstringEmail of the requester
statusstringRequest state: pendingApproval | approved | rejected
requestTypestringType of exception request
justificationstringReason given by the requester

Errors

  • 500 — Lookup failed
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List exception requests by requester

GET /policies/api/v1/policy-exception-requests/by-requester/{requestedBy}

Returns requests submitted by the given user. Not paginated.

Roles: admin

Path parameters

NameTypeDescription
requestedBystringRequester identifier, matched exactly against the stored requestedBy value

Response 200 (application/json)

PolicyExceptionRequest[] (plain array)

FieldTypeDescription
idstringRequest ID
namestringRequest name
requestedBystringUser who submitted the request
requestedByEmailstringEmail of the requester
statusstringRequest state: pendingApproval | approved | rejected
requestTypestringType of exception request
justificationstringReason given by the requester

Errors

  • 500 — Lookup failed
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List exception requests by state

GET /policies/api/v1/policy-exception-requests/by-status/{status}

Returns requests whose state exactly matches the given value. Not paginated.

Roles: admin

Path parameters

NameTypeDescription
statusstringRequest state: pendingApproval, approved or rejected (case-sensitive)

Response 200 (application/json)

PolicyExceptionRequest[] (plain array)

FieldTypeDescription
idstringRequest ID
namestringRequest name
requestedBystringUser who submitted the request
requestedByEmailstringEmail of the requester
statusstringRequest state: pendingApproval | approved | rejected
requestTypestringType of exception request
justificationstringReason given by the requester

Errors

  • 500 — Lookup failed
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted